Impact
Logto does not properly delete IdP‑initiated SAML sessions when they are no longer needed, which allows a valid session token to be reused during its validity period. This session‑replay flaw enables an attacker who has acquired a token to maintain access to the associated authenticated session without re‑authentication, potentially accessing any resources the token authorizes.
Affected Systems
Logto Logto. Affected versions are not specified in the advisory.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. If an attacker obtains a legitimate IdP‑initiated SAML session token, the token can be replayed until it reaches its expiration, providing continued authenticated access.
OpenCVE Enrichment